Microsoft Edge Information Disclosure Vulnerability
Key Information
- Vendor
- Microsoft
- Status
- Microsoft Edge (chromium-based)
- Vendor
- CVE Published:
- 25 May 2024
Badges
Summary
The vulnerability CVE-2024-30056 is an information disclosure vulnerability in Microsoft Edge, a Chromium-based web browser. The vulnerability allows unauthorized actors to access private user information, potentially posing a risk to data privacy and security. A Proof-of-Concept (PoC) exploit has been released, demonstrating the feasibility of unauthorized access to private user information. Microsoft has rated the severity of the vulnerability as "Important" with a CVSS score of 7.1 out of 10. The company is working on a patch to address the issue, but in the meantime, users are urged to exercise caution when browsing the web and ensure their browser is updated to the latest version as soon as a fix becomes available. It is important for users to stay informed, apply security patches, and exercise caution when interacting with untrusted sources.
Affected Version(s)
Microsoft Edge (Chromium-based) < 124.0.2478.109
News Articles
CVSS V3.1
Timeline
- 👾
Exploit exists.
First article discovered by CybersecurityNews
Vulnerability published.
Vulnerability Reserved.